- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortinac Rolbased vlan mapping issue
My Fortiswitches connect Fortigate with fortilink and I add my fortigate to FortiNAC when I plug new pc to fortswitch port it set to register vlan but when i login with active directory user it not maping to role based vlan
- Labels:
-
FortiNAC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is the host successfully registered in FNAC and which method is used to register the host? Is the 'Registered To' field showing the user in Hosts details?
 
If you want to use Roles, it need to be configured to match with an LDAP group and than match that in a network access policy.
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I configured it but dont work yet. I configure wireless radius authentication it works user based access but LAN LDAP role based access didnt work
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you using RADIUS authentication also for wired hosts, how are the host registered? Does the host have the 'Registered To' field completed and is the host moved to the Group?
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I dont use RADIUS authentication for wired connection I use RADIUS auth for only wireless connection. I use wired connection LDAP authentication
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I see the l2 pool failed error on fortiswitch bu fortigate fw l2 poll succed, can it affect this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When the FSW is managed from the FGT, FNAC will query only the FGT (L2/L3 polling), there is no need to enable L2 polling directly in the switch. More details are shown in the Integration guide.
In case of RADIUS authentication for wired users, FSW will act as the NAS but this is not the case for your setup.
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @isgandar
As Emirjon asked above:
Is the host successfully registered in FNAC and which method is used to register the host? Is the 'Registered To' field showing the user in Hosts details? --> If the host is not associated with a "Registered To" user, then the group cannot be matched and the role cannot be assigned.
Sx11 suggestion would also be a solution.
Follow the steps in this article: https://community.fortinet.com/t5/FortiNAC-F/Technical-Tip-Assign-Roles-based-on-User-LDAP-Directory...
BR
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would suggest to you to assing roles based on the Directory attributes of the user in LDAP instead of Directory group membership.
Follow the steps in this article: https://community.fortinet.com/t5/FortiNAC-F/Technical-Tip-Assign-Roles-based-on-User-LDAP-Directory...
